CVE Database
/

CVE-2017-8142

Back to search

CVE-2017-8142

Published: Nov 22, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability. An attacker tricks a user into installing a malicious application, and the application can start multiple threads and try to create and free specific memory, which could triggers access memory after free it and causes a system crash or arbitrary code execution.

VendorProductVersions

Huawei Technologies Co., Ltd.

Mate 9, Mate 9 Pro

affected
Versions earlier than MHA-AL00BC00B221, Versions earlier than LON-AL00BC00B221

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now